Malicious PDF — malware analysis report

Static analysis result for SHA-256 fead9a5d5d4edacd…

MALICIOUS

PDF

67.3 KB Created: 2020-10-15 12:13:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-16
MD5: 8d0ad34854f1a59359119a4b4679c668 SHA-1: a6fba1fd18c02d39e33ef69423d14caa241687ed SHA-256: fead9a5d5d4edacdfdd80a4577766f0ca2b71c5b05722c9d42f2ef3f10d68bc1
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links designed to redirect users to malicious websites, masquerading as a legitimate manual. The heuristic firings indicate a link farm and a malicious redirector, with one primary URL identified as a potential threat. No scripts were extracted, but the document structure and embedded URLs strongly suggest a phishing or redirection attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/wb?keyword=task%20force%20table%20saw%20owners%20manual In PDF document text
    • https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/bdbc33bd.pdfIn PDF document text
    • https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/82762.pdfIn PDF document text
    • https://nagifinapu.weebly.com/uploads/1/3/2/6/132696111/fafeg.pdfIn PDF document text
    • https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/d996418.pdfIn PDF document text
    • https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/kanibupopakuberasup.pdfIn PDF document text
    • https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/9611648.pdfIn PDF document text
    • https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/3e75a4e696b2f2d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365584/normal_5f870822b33b9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366377/normal_5f874452a8e94.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366961/normal_5f8755e9e12f9.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/60c784e9-345e-43fe-b61a-71d09ded4f23/jenukim.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e9cc1cfa-cd9c-48d1-bc09-23a058a45c21/95920629914.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fdf7541f-87a5-4adb-83e6-4b58b95ab357/xirutonizofev.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/66c94a7e-af79-41ec-88cd-e364c54fa27c/lizonopunox.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5ca1350b-f772-4f46-a2bb-059ae6812d2b/gujuxuvasululadunameve.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0483/1412/2404/files/sedimentology_and_stratigraphy_nichols.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0482/6985/2833/files/ancient_roman_newspaper_template.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0436/4432/1945/files/fugenabo.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0437/6153/3089/files/lilorerar.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/34053e4f-a3ad-4da1-8ed0-24389eedc498/77743769616.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/12e766e7-f8d5-4f9a-83d7-92f47791d2f0/wakukemilojidovukeja.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/710ad9be-7d50-4120-a886-107cb406ea1a/88293185000.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ac52.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAC52 5108 bytes
SHA-256: b2482e17d74132dc5438b1031f35b96fd25df0dc465c3f02930409de9a37ae63
font_01_sfnt_off0000bdaa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBDAA 2836 bytes
SHA-256: bfb6003743e6b9126238e90675f729fbb6dc2f58e4a949e27fe9f2faf3d87155
font_02_sfnt_off0000c98d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC98D 11988 bytes
SHA-256: 24e384253cad453db5bdc7a8d63fa002edd29dd1d402d20b0e8cbff1461175dc
font_03_sfnt_off0000f0b7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF0B7 4324 bytes
SHA-256: b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c